HG10
Tenda- Software type
- —
- Catalog vulnerabilities
- 13
Severity across 13 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 13 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, HG10 has 6 security vulnerabilities published in the last 90 days. Of these, 6 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of HG10 and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-86167Tenda HG10 Boa formgponConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityCritical |
CVE-2026-86166Tenda HG10 Boa Web Server formWanRedirect buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityHigh |
CVE-2026-86165Tenda HG10 formURL buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2026 | SeverityCritical |
CVE-2026-85110Tenda HG10 Boa Web Server formWlanSetup buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/03/2026 | SeverityHigh |
CVE-2026-85109Tenda HG10 Boa Web Server formLogin buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/03/2026 | SeverityCritical |
CVE-2026-82542Tenda HG10 Boa Web Server formIPv6Routing buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published08/30/2026 | SeverityCritical |
CVE-2026-11553Tenda HG7HG9/HG10 formPPPEdit stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2026 | SeverityHigh |
CVE-2026-11499Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published06/08/2026 | SeverityCritical |
CVE-2026-11498Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published06/08/2026 | SeverityHigh |
CVE-2026-6988Tenda HG10 Boa Service formRouting formRoute buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/25/2026 | SeverityHigh |
CVE-2026-1690Tenda HG10 formSysCmd system command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |
CVE-2026-1689Tenda HG10 Login formLogin checkUserFromLanOrWan command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |
CVE-2026-1687Tenda HG10 Boa Webserver formSamba command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/30/2026 | SeverityMedium |